Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-30943


The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.


Published

2023-05-02T20:15:10.943

Last Modified

2024-11-21T08:01:07.563

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-73
  • Type: Primary
    CWE-610

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application moodle moodle < 4.1.3 Yes
Application fedoraproject extra_packages_for_enterprise_linux 7.0 Yes
Operating System fedoraproject fedora 36 Yes
Operating System fedoraproject fedora 37 Yes
Operating System fedoraproject fedora 38 Yes

References